Fifteen-plus years in and around this, most of it not in public. OSINT work, red team engagements, tooling nobody but the client ever saw. Affiliated with Anonymous since '09, back when it still meant something to say that out loud.
I build the tools I can't find, break the things that deserve breaking, and write up the parts of it that are safe to write up. Everything else stays a case file.
root@spydirbyte:~$ whoami
[+] hacktivist, since 2009
[+] OSINT / threat intel / digital investigations
[+] red team, adversary simulation, vuln research
[+] privacy & OPSEC advocate -- information belongs to everyone
- OSINT & investigations -- GEOINT, SOCMINT, HUMINT, metadata analysis, the kind of digging that turns a username into a case file
- red team / offensive security -- pentesting, adversary simulation, social engineering, vuln assessment
- privacy & OPSEC -- digital footprint reduction, anonymity infrastructure, threat modeling for people who actually need it
- building -- security tooling, automation, full-stack (Next.js / Python / Go / C++ and whatever the job calls for)
- teaching -- walked 50+ people through the fundamentals of this work, most of it for free
Threat Intelligence OSINT & Investigations Penetration Testing Red Team Operations
Social Engineering Vulnerability Assessment Adversary Simulation Digital Footprint Reduction
Operational Security Secure Infrastructure WAF Configuration AI/ML Integration
30+ operations logged since 2011. OP_TUNISIA, OP_ANTISEC, OP_NSA, FREEDOMHOSTING_TAKEDOWN, OP_FERGUSON, OP_HONG_KONG, OP_GEORGE_FLOYD, OP_RUSSIA, OP_IRAN, OP_FREE_PALESTINE among them. Some made headlines, most didn't. That was usually the point.
Full writeup: spydirbyte.github.io
| repo | what it does |
|---|---|
spydir-os |
Free OSINT course run as a simulated hacker OS -- 8 case files, real desktop, interactive terminal. Zero backend. |
spy-geoint |
GEOINT workspace -- shadow-angle sun calculator, EXIF/GPS extraction, optional AI vision clue extraction |
spydir-opsec |
Practical OPSEC course delivered as an interactive terminal, not another docs site |
spy-privacy-pulse |
Self-hosted privacy checkup dashboard -- breach monitoring, broker opt-out tracking, exposure mapping |
spy-osint-suite |
Docker-ready OSINT toolkit -- username enum, HIBP checks, domain recon, metadata extraction |
spy-recon-mapper |
Shodan-powered recon for the internet's exposed devices, mapped and scored over time |
spy-threat-hunt |
IOC extraction and hunt query generation, for analysts tired of doing it by hand |
spy-kernel-triage |
Traces flagged static-analyzer output through a real kernel call graph |
information belongs to everyone.